summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* Merge remote-tracking branch 'origin/mr/102'Nick Mathewson2021-10-266-55/+350
|\
| * Overhaul the way WaitFor and the MockSleepProvider worketa2021-10-266-55/+350
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Instead of racily advancing time forward, this commit attempts to rework how WaitFor works, such that it makes advances when all sleeper futures that have been created have been polled (by handing the MockSleepRuntime a Waker with which to wake up the WaitFor). The above described mechanics work well enough for the double timeout test, but fail in the presence of code that spawns asynchronous / background tasks that must make progress before time is advanced for the test to work properly. In order to deal with these cases, a set of APIs are introduced in order to block time from being advanced until some code has run, and a carveout added in order to permit small advances in time where required. (In some cases, code needed to be hacked up a bit in order to be made properly testable using these APIs; the `MockablePlan` trait included in here is somewhat unfortunate.) This should fix arti#149.
* | Merge branch 'pb_lite_squashed'Nick Mathewson2021-10-265-11/+236
|\ \
| * | Avoid a strange borrow syntax in tor_guardmgr::sampleNick Mathewson2021-10-261-3/+3
| | | | | | | | | | | | I'm not sure what I was thinking here.
| * | Do not blame a guard for failures on non-random circuits.Nick Mathewson2021-10-262-4/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | We must not apply our new path-bias behavior (where we blame a guard if it gives us too many indeterminate circuit failures) if the path was not chosen at random. If too many random paths fail, we know that's suspicious, since the other relays are a random sample. But if a bunch of user-provided paths fail, that could simply be because the user's chosen exit is down.
| * | Implement a "lightweight" form of pathbias detection.Nick Mathewson2021-10-263-5/+193
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We now track, for every guard: the total number of successful circuits we've built through it, along with the total number of "indeterminate" circuits. Recall that a circuit's status is "indeterminate" if it has failed for a reason that _might_ be the guard's fault, or might not be the guard's fault. For example, if extending to the second hop of the circuit fails, we have no way to know whether the guard deliberately refused to connect there, or whether the second hop is just offline. But we don't want to forgive all indeterminate circuit failures: if we did, then a malicious guard could simply reject any second hops that it didn't like, thereby filtering the client into a chosen set of circuits. As a stopgap solution, this patch now makes guards become permanently disabled if the fraction of their circuit failures becomes too high. See also general-purpose path bias selection (arti#65), and Mike's idea for changing the guard reachability definition (torspec#67). This patch doesn't do either of those. Closes #185.
* | | Tests and refactoring for IsolationMap.Nick Mathewson2021-10-261-13/+50
| | |
* | | TorClient::resolve_ptr should take an IpAddr.Nick Mathewson2021-10-263-10/+14
| | |
* | | More tests for arti_client::addressNick Mathewson2021-10-261-15/+106
| | |
* | | Merge branch 'isolate_clients'Nick Mathewson2021-10-263-55/+134
|\ \ \
| * | | Turn StreamIsolation into a separate type.Nick Mathewson2021-10-253-43/+103
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now that we have two kinds of isolation tokens (those set on a stream, and those set by the stream's associated TorClient), we need a more sophisticated kind of isolation. This fixes the bug introduced with the previous commit, where per-stream tokens would override per-TorClient tokens.
| * | | Add an isolate_client() function to create an isolated TorClient.Nick Mathewson2021-10-251-15/+34
| |/ / | | | | | | | | | | | | When two TorClients are isolated, their streams shouldn't share circuits, even though they share internal circuit and guard state.
* | | Upgrade curve25519-dalek requirement to 3.2.0Nick Mathewson2021-10-251-1/+1
| | | | | | | | | | | | We need this now that we check for contributory behavior.
* | | Fix typos and cleanupDimitris Apostolou2021-10-255-9/+9
|/ /
* | guardmgr: Don't use guards that are marked as unlisted.Nick Mathewson2021-10-252-7/+22
| | | | | | | | Closes #202.
* | s/arti-arti-client/arti-client/ and regenerate readme filesNick Mathewson2021-10-255-6/+6
| |
* | Fix a typo in a comment.Nick Mathewson2021-10-251-1/+1
| |
* | Remove chrono exception from cargo_audit.shNick Mathewson2021-10-241-13/+17
| |
* | Migrate tor-dirmgr from chrono to time 0.3Nick Mathewson2021-10-244-64/+44
| | | | | | | | | | (This appears to be the emerging consensus of how to handle RUSTSEC-2020-0159.)
* | Migrate tor-netdoc from chrono to time 0.3Nick Mathewson2021-10-243-6/+9
| | | | | | | | | | (This appears to be the emerging consensus of how to handle RUSTSEC-2020-0159.)
* | Upgrade to latest tracing-{subscriber,journald}Nick Mathewson2021-10-233-23/+9
| |
* | Upgrade to new version of simple_asn1.Nick Mathewson2021-10-222-5/+32
| |
* | Run "cargo fix --edition-idioms=2018".Nick Mathewson2021-10-224-5/+5
| |
* | Replace references to arti-client in the documentation.Nick Mathewson2021-10-218-11/+11
| |
* | Rename tor_client/arti_tor_client to arti_client.Nick Mathewson2021-10-2116-36/+28
| | | | | | | | | | | | Solves a name conflict with the existing tor_client create. Closes #130.
* | Remove #![allow(clippy::unnecessary_wraps)] in tor-proto.Nick Mathewson2021-10-211-1/+0
| |
* | Remove #![allow(unreachable_pub)] in shared_ref.rsNick Mathewson2021-10-211-7/+5
| |
* | Remove #![allow(clippy::unwrap_used)] in cmdline.rsNick Mathewson2021-10-211-1/+0
| |
* | Remove #![allow_unused] in tor_chanmgr::mgrNick Mathewson2021-10-212-1/+4
| |
* | Remove #![allow(dead_code)] in timeouts.rsNick Mathewson2021-10-212-2/+3
| |
* | Merge branch 'share_state'Nick Mathewson2021-10-2120-330/+718
|\ \
| * | Implement the guard side of shared state directories.Nick Mathewson2021-10-214-3/+51
| | |
| * | Mark consensus as "not-pending" even if its microdescs come from cache.Nick Mathewson2021-10-203-8/+48
| | | | | | | | | | | | | | | | | | | | | Previously our code would clear the 'pending' flag on a consensus only when a _downloaded_ md made it become usable. Closes #199.
| * | Move tor-dirmgr to use a sync::Mutex.Nick Mathewson2021-10-203-45/+36
| | | | | | | | | | | | | | | The futures::lock::Mutex was unnecessary, since we never held it when we were suspending.
| * | Finish the timeout-inference side of shared state.Nick Mathewson2021-10-204-32/+113
| | |
| * | Add a timeout estimator to take estimates from another process.Nick Mathewson2021-10-204-42/+93
| | |
| * | Allow type of timeout estimator to change at runtime.Nick Mathewson2021-10-205-201/+298
| | | | | | | | | | | | | | | | | | This is a big change, but it does simplify the type of Builder a little, and isolates locking across different (potential) timeout estimator types.
| * | Remove try_lock from StorageHandle.Nick Mathewson2021-10-202-8/+2
| | |
| * | Replace the return type of StorageMgr::try_lock with a tristateNick Mathewson2021-10-208-46/+86
| | | | | | | | | | | | | | | It's useful to know now only if we now have the lock, but also if we just got it for the first time.
| * | Initial work on periodically reloading state.Nick Mathewson2021-10-194-28/+54
| | | | | | | | | | | | | | | We can use this in the case where we don't get the lock on the state file, because another process is running.
| * | On startup, try to lock the state file, and log whether we succeed.Nick Mathewson2021-10-191-1/+9
| | | | | | | | | | | | | | | Previously we'd try to grab the lock the first time we wrote to the file.
* | | fallbackdir: Regenerate list for October 2021David Goulet2021-10-211-881/+870
| |/ |/| | | | | | | | | Closes #200 Signed-off-by: David Goulet <[email protected]>
* | Remove unused d_pre from DiffResult.Nick Mathewson2021-10-201-24/+15
| |
* | Implement the "request_loyalty" configuration optionNick Mathewson2021-10-191-2/+1
| |
* | Fix most warnings from nightly.Nick Mathewson2021-10-1911-21/+24
| | | | | | | | (One represents code that I forgot to write.)
* | Fix a broken rustdoc link.Nick Mathewson2021-10-191-1/+1
| |
* | tor-client/examples: add `hyper` exampleeta2021-10-193-2/+253
| | | | | | | | | | | | | | The new `hyper` tor-client example demonstrates integrating arti with the popular Rust `hyper` HTTP library by implementing a custom Hyper "connector" (a type that can initiate connections to HTTP servers) that proxies said connections via the Tor network.
* | Also implement tokio Async{Read,Write} on Data{Reader,Writer}.Nick Mathewson2021-10-191-5/+31
| | | | | | | | | | | | | | | | This will let callers use the tokio traits on these types too, if they call `split()` on the DataStream. (Tokio also has a `tokio::io::split()` method, but it requires a lock whereas `DataStream::split()` doesn't.)
* | Add a little documentation about when you'll need the tokio trait.Nick Mathewson2021-10-191-0/+7
| |
* | Merge remote-tracking branch 'origin/mr/97'Nick Mathewson2021-10-194-1/+40
|\ \